You don't need a device package and this should work fine...device package is certainly nice but can introduce some complexity as well depending on your use case. If you are generally static without a ton of change (spinning workloads up and down etc.) then you can just use it as you would any other firewall and leverage policy in the ACI fabric to direct traffic to it. Here's a good example of how:https://community.cisco.com/t5/data-center-documents/aci-unmanaged-mode-configuration-example-using-asav-in-routed/ta-p/3313318
... View more